<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IOC Feed from Infoblox in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/202656#M38133</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am trying to get Exernal Threat Intel feed for DNS from Infoblox but the expected format from CP is different from the API request&amp;nbsp; format I get from Infoblox.&lt;/P&gt;&lt;P&gt;Has anyone tried this before ? I am not sure how to feed in the API Key into the feed URL.&lt;/P&gt;&lt;P&gt;Below is the API Request format from IB and I have attached the smartconsole parameters in CP for the IOC feed.&lt;/P&gt;&lt;P&gt;curl -X GET -H "Authorization: Token token=&amp;lt;API_KEY&amp;gt;" "&lt;A href="https://csp.infoblox.com/tide/api/data/threats?type=host&amp;amp;type=ip&amp;amp;type=url&amp;amp;type=email&amp;amp;type=hash" target="_blank"&gt;https://csp.infoblox.com/tide/api/data/threats?type=host&amp;amp;type=ip&amp;amp;type=url&amp;amp;type=email&amp;amp;type=hash&lt;/A&gt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate any directions here !&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Srini&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jan 2024 06:13:43 GMT</pubDate>
    <dc:creator>SriniKrish</dc:creator>
    <dc:date>2024-01-10T06:13:43Z</dc:date>
    <item>
      <title>IOC Feed from Infoblox</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/202656#M38133</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am trying to get Exernal Threat Intel feed for DNS from Infoblox but the expected format from CP is different from the API request&amp;nbsp; format I get from Infoblox.&lt;/P&gt;&lt;P&gt;Has anyone tried this before ? I am not sure how to feed in the API Key into the feed URL.&lt;/P&gt;&lt;P&gt;Below is the API Request format from IB and I have attached the smartconsole parameters in CP for the IOC feed.&lt;/P&gt;&lt;P&gt;curl -X GET -H "Authorization: Token token=&amp;lt;API_KEY&amp;gt;" "&lt;A href="https://csp.infoblox.com/tide/api/data/threats?type=host&amp;amp;type=ip&amp;amp;type=url&amp;amp;type=email&amp;amp;type=hash" target="_blank"&gt;https://csp.infoblox.com/tide/api/data/threats?type=host&amp;amp;type=ip&amp;amp;type=url&amp;amp;type=email&amp;amp;type=hash&lt;/A&gt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate any directions here !&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Srini&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 06:13:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/202656#M38133</guid>
      <dc:creator>SriniKrish</dc:creator>
      <dc:date>2024-01-10T06:13:43Z</dc:date>
    </item>
    <item>
      <title>Re: IOC Feed from Infoblox</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203257#M38242</link>
      <description>&lt;P&gt;What format does Infoblox provide information in?&lt;BR /&gt;If it's JSON, I recommend upgrading to R81.20 and using the Network Feeds option, which can read JSON with a provided jq filter.&lt;BR /&gt;If your IOC feed is large, you should upgrade to R81.20 as the supported number of IoCs is much higher (at least 2 million IoCs have been tested) and they are imported significantly faster to boot.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 18:55:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203257#M38242</guid>
      <dc:creator>phoneboyapi</dc:creator>
      <dc:date>2024-01-16T18:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: IOC Feed from Infoblox</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203260#M38243</link>
      <description>&lt;P&gt;Let me test it in my R81.20 lab&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 19:29:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203260#M38243</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-16T19:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: IOC Feed from Infoblox</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203262#M38244</link>
      <description>&lt;P&gt;this worked for me&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24083i7BFB2310855B1084/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 19:43:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203262#M38244</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-16T19:43:20Z</dc:date>
    </item>
    <item>
      <title>Re: IOC Feed from Infoblox</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203282#M38253</link>
      <description>&lt;P&gt;Those feeds are only available to Infoblox customers or are those open to anyone to test that out?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 03:07:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203282#M38253</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2024-01-17T03:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: IOC Feed from Infoblox</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203294#M38257</link>
      <description>&lt;P&gt;Interesting !&lt;/P&gt;&lt;P&gt;How did you key in the API key ? I don't see an option in the IOC Feed pop up dialog.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Srini&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 06:49:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203294#M38257</guid>
      <dc:creator>SriniKrish</dc:creator>
      <dc:date>2024-01-17T06:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: IOC Feed from Infoblox</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203296#M38258</link>
      <description>&lt;P&gt;Infoblox customers only. But you can set up a test environment with 60 day licensing and it pretty much gives access to DHCP, DNS and Threat feeds as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Srini&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 06:51:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203296#M38258</guid>
      <dc:creator>SriniKrish</dc:creator>
      <dc:date>2024-01-17T06:51:12Z</dc:date>
    </item>
    <item>
      <title>Re: IOC Feed from Infoblox</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203297#M38259</link>
      <description>&lt;P&gt;It is pretty much in the format above. I did try to feed through Mgmt_cli but getting the API key across has been challenge. I see Andy was able to connect via the Smartconsole. keen to know how he used the API key.&lt;/P&gt;&lt;P&gt;Srini&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 06:57:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203297#M38259</guid>
      <dc:creator>SriniKrish</dc:creator>
      <dc:date>2024-01-17T06:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: IOC Feed from Infoblox</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203334#M38284</link>
      <description>&lt;P&gt;I just did it exactly how you see in the screencap, via smart console.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 12:28:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203334#M38284</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-17T12:28:06Z</dc:date>
    </item>
    <item>
      <title>Re: IOC Feed from Infoblox</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203337#M38286</link>
      <description>&lt;P&gt;Sorry I don't understand.  there are no fields to key in the API key. How will it map user authentication in the cs portal without the API key ?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_20240117_233033_Firefox.jpg" style="width: 1055px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24091i6F6179F0A2A1BAE6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_20240117_233033_Firefox.jpg" alt="Screenshot_20240117_233033_Firefox.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 12:35:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203337#M38286</guid>
      <dc:creator>SriniKrish</dc:creator>
      <dc:date>2024-01-17T12:35:18Z</dc:date>
    </item>
    <item>
      <title>Re: IOC Feed from Infoblox</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203344#M38290</link>
      <description>&lt;P&gt;K, I gotcha now. Sorry, I just tested the actual link in the smart console feed menu, thats all.&lt;/P&gt;
&lt;P&gt;You may need to confirm with TAC.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 13:21:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203344#M38290</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-17T13:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: IOC Feed from Infoblox</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203349#M38291</link>
      <description>&lt;P&gt;Here is file I created and worked fine. Just convert it to csv format to import.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 13:56:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203349#M38291</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-17T13:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: IOC Feed from Infoblox</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203436#M38333</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried the same by using the api service username and API key as password in the Advanced field and it did accept.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IS there a way to validate if it is receiving any feeds at all ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Srini&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 05:11:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203436#M38333</guid>
      <dc:creator>SriniKrish</dc:creator>
      <dc:date>2024-01-18T05:11:07Z</dc:date>
    </item>
    <item>
      <title>Re: IOC Feed from Infoblox</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203475#M38343</link>
      <description>&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk132193" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk132193&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2024 12:43:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IOC-Feed-from-Infoblox/m-p/203475#M38343</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-01-18T12:43:17Z</dc:date>
    </item>
  </channel>
</rss>

